Impact
Use after free in the V8 JavaScript engine of Google Chrome versions prior to 153.0.8010.36 allows a remote attacker, who has previously compromised the renderer process, to read memory inside the browser’s sandbox by serving a specially crafted HTML page. This flaw can expose sensitive data processed by the renderer, but it does not grant arbitrary code execution or system-wide control.
Affected Systems
The vulnerability affects all installations of Google Chrome older than 153.0.8010.36, because the flaw resides in the V8 component embedded in the renderer process.
Risk and Exploitability
The flaw requires an attacker to first compromise the renderer process, which might be achieved through a separate vulnerability or by deceiving the user into loading malicious web content. Once that precondition is met, the attacker can inject a crafted payload that triggers the use‑after‑free, enabling memory reading. The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, further indicating currently limited observed exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA